Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 330

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Trump's AI executive order nears key deadline as regulation debate intensifies
S&P 500 closes higher Friday as Amazon surges; Dow posts fourth straight winning month: Live updates
450,000 defrauded student loan borrowers are eligible for debt forgiveness — here's who qualifies
Pirro moves to drop case against Olympian, says Reflecting Pool damage caused by 'flawed installation'
August kicks off next week with jobs report, earnings as momentum recovers. Here's what's ahead
Building for 131°F: Europe races to protect its infrastructure from a ‘quiet catastrophe’
Book: The Headache by Tom Zeller Jr
Movie: Please Turn Over
Movie: Spider-Man: Brand New Day
Buy these stocks ahead of earnings. Bank of America says they offer plenty of upside